Securing Your Account - Two-Factor Sign-In and Passkeys

With two-factor authentication (2FA) and passkeys you secure your SEOFuxx account so that a stolen password alone is no longer enough.

What options are there?

Option How it works
Password The classic way. Pick a long password that you use only here.
Two-factor authentication In addition to the password you enter a 6-digit code from an authenticator app.
Passkey You sign in without a password, using Face ID, Touch ID, Windows Hello or a security key.
Google / GitHub Sign in with your existing account at the respective provider.

You'll find 2FA and passkeys in the account on the Security tab.

Set up two-factor authentication

For that you need an authenticator app on your smartphone, for example Google Authenticator, Microsoft Authenticator, Aegis or 1Password.

  1. Open Account and the Security tab
  2. Switch on 2FA via authenticator app
  3. Scan the QR code with your app. Alternatively, enter the secret shown manually in the app.
  4. Enter the 6-digit code from the app
  5. Click Confirm

The status then shows Active, and you're done.

How to sign in with 2FA

  1. Enter email and password as usual
  2. The Two-factor sign-in page appears
  3. Enter the current 6-digit code from the app

The code changes every 30 seconds. If it's rejected, look at your device's clock, because if it's off, the code won't match either.

Switch 2FA off

Set the toggle on the Security tab back to off and confirm the question "Really disable two-factor authentication?".

Careful: There are no recovery codes. If you lose the device with your authenticator app, you can no longer get into the account. So use an app with backup or device sync, such as a password manager, or set up a passkey as well. If something goes wrong, support helps via the contact form.

Passkeys

A passkey replaces the password with a cryptographic key pair whose secret part never leaves your device. That helps against phishing, because a passkey only works on the real SEOFuxx site.

Add a passkey

  1. Open Account and the Security tab
  2. Optionally enter a Device name, e.g. "MacBook", "iPhone" or "YubiKey"
  3. Click Add new passkey
  4. Confirm with Face ID, Touch ID, Windows Hello or your security key

The list shows all registered passkeys. Several are possible, for example one per device.

Sign in with a passkey

On the login page you click Sign in with passkey and confirm on the device. You don't need a password then.

Recommendations

  1. Enable 2FA, especially if projects, invoices or a subscription hang on your account
  2. Set up a passkey as well, ideally on two devices, so you're never locked out
  3. Use a password only here, preferably from a password manager
  4. Change your password as soon as you suspect misuse (see Account: domain and password)
  5. Keep API keys secret and revoke them in the account if in doubt (see API v1 quickstart)

Frequently asked questions

The code is not accepted

Check that you're entering the current code (it changes every 30 seconds) and that your device's date and time are set automatically.

Do I need 2FA if I have a passkey?

A passkey is more secure than a password by itself. You decide at each login which method you use. 2FA additionally protects signing in with a password.

Can I delete passkeys again?

Yes, in the list on the Security tab.

I forgot my password

Click Forgot password? on the login page.

Is this content helpful?

·